Security Hardener

👤 mariusfit 📦 v1.0.0 ⭐ 4.4 ⬇️ 2.8K 下載
🔒 IT運維與安全 免費

📖 技能介紹


name: security-hardener description: Audit and harden OpenClaw configuration for security. Scans openclaw.json for vulnerabilities, exposed credentials, insecure gateway settings, overly permissive exec rules, and missing security best practices. Use when asked to audit security, harden configuration, check for vulnerabilities, or secure an OpenClaw deployment.


Security Hardener

Audit your OpenClaw configuration and apply security best practices automatically.

Quick Start

# Full security audit (read-only, no changes)
python scripts/hardener.py audit

# Audit a specific config file
python scripts/hardener.py audit --config /path/to/openclaw.json

# Audit with JSON output
python scripts/hardener.py audit -f json

# Auto-fix issues (creates backup first)
python scripts/hardener.py fix

# Fix specific issues only
python scripts/hardener.py fix --only gateway,permissions

# Scan for exposed credentials in config
python scripts/hardener.py scan-secrets

# Generate a security report
python scripts/hardener.py report -o security-report.md

# Check file permissions
python scripts/hardener.py check-perms

Commands

Command Args Description
audit [--config PATH] [-f FORMAT] Full security audit (read-only)
fix [--config PATH] [--only CHECKS] Auto-fix issues (with backup)
scan-secrets [--config PATH] Scan for exposed API keys/tokens
report [-o FILE] Generate detailed security report
check-perms [--config-dir PATH] Check file permissions

Security Checks

Check Severity Description
gateway-bind CRITICAL Gateway not bound to loopback
exposed-keys CRITICAL API keys in config instead of .env
insecure-auth HIGH allowInsecureAuth or dangerouslyDisableDeviceAuth enabled
exec-sandbox HIGH exec sandbox mode not set to restricted
file-perms HIGH Config files readable by others (not 600)
agent-allow-all MEDIUM agentToAgent.allow: ["*"] is overly permissive
no-heartbeat MEDIUM No heartbeat configured (can't detect outages)
no-session-reset MEDIUM No session reset policy (memory leak risk)
no-pruning LOW No context pruning (cost and performance impact)
no-memory-flush LOW Memory flush disabled (context loss on pruning)

Scoring

The audit produces a security score from 0-100: - 90-100: Excellent — production-ready - 70-89: Good — minor improvements recommended - 50-69: Fair — several issues to address - 0-49: Poor — critical issues require immediate attention

Example Output

╔══════════════════════════════════════════════════╗
║  OPENCLAW SECURITY AUDIT                         ║
╠══════════════════════════════════════════════════╣
║  Score: 75/100 (Good)                            ║
║                                                  ║
║  ✅ Gateway bound to loopback                    ║
║  ✅ No exposed API keys in config                ║
║  ⚠️  exec sandbox mode: unrestricted             ║
║  ⚠️  agentToAgent allow: * (too permissive)      ║
║  ❌ File permissions too open (644 → should be 600) ║
║  ✅ Heartbeat configured                         ║
║  ✅ Session reset policy active                   ║
║  ⚠️  No context pruning configured               ║
╚══════════════════════════════════════════════════╝

7w4.net提供免費和付費技能下載。

🤖 AI 評測

這是一款實用的安全審計工具,能自動檢測 OpenClaw 配置中的10類安全隱患,並支援一鍵修復。介面友好、輸出清晰,修復前會自動備份。評分系統讓安全狀況一目瞭然。扣分項是部分功能偶有小問題,以及缺少詳細的配置說明文件。總體而言質量可靠,能有效提升部署安全性,適合對安全有要求的使用者使用。

📊 多維度評分

適應性4.5
規範性4.3
有效性4.3
可靠性4.4
可信度4.5

📁 包含檔案 (4 個)

📄 README.md 1.4 KB
📄 SKILL.md 3.7 KB
📄 _meta.json 139 B
📄 scripts/hardener.py 16.1 KB